19:07:18 #startmeeting Ansible Lockdown Working Group 19:07:18 Meeting started Thu May 7 19:07:18 2020 UTC. 19:07:18 This meeting is logged and archived in a public location. 19:07:18 The chair is cyberpear. Information about MeetBot at http://wiki.debian.org/MeetBot. 19:07:18 Useful Commands: #action #agreed #halp #info #idea #link #topic. 19:07:18 The meeting name has been set to 'ansible_lockdown_working_group' 19:07:28 #chair dfed[m] xgeorgex 19:07:28 Current chairs: cyberpear dfed[m] xgeorgex 19:07:34 #topic Roll Call 19:07:41 who's here for Lockdown WG meeting today? 19:09:26 .hello2 19:09:27 cyberpear: cyberpear 'James Cassell' 19:09:31 is it just me today? 19:11:31 #topic generic Linux OS Lockdown role 19:12:41 #info https://github.com/jamescassell/lockdown-linux is a proof-of-concept multi-standard, multi-OS role for locking down/hardening systems according to CIS or STIG 19:15:48 the role currently configures MACs and Ciphers in sshd_config 19:16:21 I've tested it on Ubuntu 18.04, RHEL 7, OpenSUSE LEAP 19:16:51 it works both in a container, and on a live system -- "live system" being defined as having an init system running. 19:18:48 still needs a README 19:44:42 it doesn't work self-hosted on RHEL 6 because python2.6 support went away in ansible-2.7, and ansible-2.7 is the oldest version where the POC works currently 19:46:20 it otherwise works on RHEL 6, and can be self-hosted if you run modern ansible in a python virtualenv and send `-e ansible_python_interpreter=/usr/bin/python` 19:46:38 #topic Open Floor 19:46:46 anyone else have anything to discuss? 20:04:06 #endmeeting